Code Injection Vulnerability in dot-access by ntharim
CVE-2026-107700

9.3CRITICAL

Key Information:

Vendor

Ntharim

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107700?

The dot-access package, versions 0.0.3 through 1.0.0, exposes a serious code injection vulnerability that can be exploited by remote attackers. By providing specially crafted paths to the get() function, an attacker can leverage JavaScript execution capabilities inherent in Node.js. This vulnerability occurs because the injected paths are concatenated into a new Function body in the index.js file, enabling access to constructor.constructor, which can lead to the execution of arbitrary operating system commands within the Node.js process. Users of the affected versions are strongly encouraged to update to the latest version to mitigate the risk associated with this issue.

Affected Version(s)

dot-access 0.0.3 <= 1.0.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

William Pierson (Retro16)
.